Computing.Net > Forums > Security and Virus > Am infected with nasty virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Am infected with nasty virus

Reply to Message Icon

Name: bmovies
Date: October 31, 2008 at 19:31:00 Pacific
OS: windows xp
CPU/Ram: pentium dual core
Product: Dell
Comment:

Actually more than one virus it seems.

Damn, but I did something stupid and downloaded something I shouldnt have. When I downloaded this virus, the cmd screen came up and showed the following: crack.exe, serial.exe, number.exe, keygen.exe AND readme.bat

I panicked, deleted those things, but it hasnt fixed my problem. It seems to have hijacked my internet explorer browser. When I click on the IE icon, it brings up the IE browser for all of a second or two before closing. (So, I'm using Firefox to browse the web, which is working, thankfully) Oh, the IE browser does appear, that is when one of those pop up advertisements comes up. Which I have NO control over. It comes up whenever it feels like it, then it stays open untill I close it. BUT I cannot use it to browse the web as there are no buttons, tool bar, address box, etc.

And it seems to prevent me from running/installing spyware. Oh, I can download the applications of some spyware programs, but then when I try to download, the damn virus wont let it! I do not know the name of this virus.

Some spyware programs seem to be able to download, but when I run them, they seem to have failed in getting rid of it. (I am using freeware as I do not have any money to buy a good anti virus program) Some seem to do more harm than good as one such program seems to have made me delete some important windows files because when I try to shut down my computer, it gives me a blue screen and an error message. So I have to manually turn it off, but even sometimes that doesnt work, so I have to unplug it.

Please, how can I find this malicious virus and get rid of it? Preferably with freeware. So many sites ask for money for their full removal service, and I cant afford their prices. Even if I could, what with info stealing viruses on my computer, i'm not about to use my computer to send my credit card info over the net!

I have run a scan with some freeware spy scanning programs and much to my shock they revealed over 250 problems. worse of which are named "spyware.igmonster", zlob, (also spelled out by one scanning program as zlop (with a "p"), trojan.infostealer.bankers

What can I do?



Sponsored Link
Ads by Google

Response Number 1
Name: jabuck
Date: October 31, 2008 at 19:38:07 Pacific
Reply:

Download SDFix.exe and save it to your Desktop.
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with SDFix or remove some of its embedded files which may cause "unpredictable results".
Click on This Link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
Remember to re-enable the protection again afterwards before connecting to the Internet.

1.Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
2. Open the c:\SDFix folder and double click RunThis.cmd to start the script.
Type Y to begin the script.
It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
3. Your system will take longer that normal to restart as the fixtool will be running and removing files.
When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
4. Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt

Please download Malwarebytes' Anti-Malware from one of these sites:

MalwareBytes1

MalwareBytes2

1. Double Click mbam-setup.exe to install the application.
2. Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
3. If an update is found, it will download and install the latest version.
4. Once the program has loaded, select "Perform Quick Scan", then click Scan. The scan may take some time to finish,so please be patient.
5. When the scan is complete, click OK, then Show Results to view the results.
6. Make sure that everything found is checked, and click Remove Selected.
7. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
8. The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
9. Copy&Paste the entire report in your next reply.


Please download and install the latest version of HijackThis v2.0.2:


Download the "HijackThis" Installer from this link:
Hijack This


1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.


0

Response Number 2
Name: bmovies
Date: October 31, 2008 at 20:32:12 Pacific
Reply:

NOW the problem is WORSE!!! Before, like I said, I had trouble with shutting down the computer. I would try to shut the computer down normally, it would seem to shut down, but then end with a blue screen with the folllowing message;

STOP: c00021a (Fatal System Error) The Windows Logon Process System process terminated unexpectedly with a status of 0x00000000 (0x00000000 0x00000000) The system has been shut down

And the computer wouldnt do anything! It would just sit there with that message staring at me. Oh, I would try to shut down the computer by pressing the power button on the tower, but even that wouldnt work! I would have to unplug the computer to get it to shut off.!

However, after unplugging it, and restarting it, I had no problem with. Untill I took your advice and installed SDFix, the safe mode bit, etc. Then the SDFix told me it would restart the computer. Fine. BUT then I got the above "fatal system error" problem when it tried to start up! NOW I'm getting it when I'm trying to start up my computer! I've tried to get around that by starting it in safe mode again, but then I just get that fatal system error message again! Jesus!

Maybe I did delete an important windows file? How can I fix this new problem?

(I am posting this message using my brothers computer in another room in the house, its the only way I can use a computer and get online for now!)


0

Response Number 3
Name: jabuck
Date: October 31, 2008 at 20:52:55 Pacific
Reply:

Download Malwarebytes to a cd on your brothers computer and try to run malwarebytes from the cd on the infected computer. You won't be able to update it but run it without updating it.


0

Response Number 4
Name: bmovies
Date: October 31, 2008 at 21:13:44 Pacific
Reply:

What will malwarebytes do for my computer? I mean, I assumed the malwarebytes is for virus things. Is it also good for helping repair the above fatal syste merror thing?


0

Response Number 5
Name: BatchFreak
Date: October 31, 2008 at 21:43:57 Pacific
Reply:

I gotta say this virus is mean...

Try jabuck's suggestion, if you cant run it from the cd,

find a windows xp boot disk... (You know that thing noone remembers where they put when they need it?) And try to boot from disk,

if you still cant, find a ms-dos start up disk and copy all you files to a diskette, alll the ones you couldnt stand losing.

Then attempt to use malware bytes from the dos prompt


If all else fails... and you cant acces your pc at all Open up your computer case and remove the bios battery. Wait 20 minutes and put it back in, then reinstall windows.

IF THAT doesnt work, 1 of two things, youve screwed one part of yor pc ( Harddrive), or the whole thing.

I only Batch if possible, 2000 more lines of code, oh well.


0

Related Posts

See More



Response Number 6
Name: BatchFreak
Date: October 31, 2008 at 21:45:01 Pacific
Reply:

Ive got the blue sreen of death before... And I ended up buying a whole new computer, cause I had a cmos virus.

I only Batch if possible, 2000 more lines of code, oh well.


0

Response Number 7
Name: jabuck
Date: November 1, 2008 at 05:11:56 Pacific
Reply:

From your description of the viral activity on your computer the culprit in Antivirus 2008/2009 and/or fake alert which are both trojan vundo.

I doubt if the computer is toast. The mobo's cmos is doubtfully the problem. The malware has most likely caused the computer to blue screen.

You could take the hard drive out, and slave it (if ide) or just add it to another computer (if sata), and run Malwarebytes on that drive from a different computer. Malwarebytes should resolve the issue if it can be run on the computer.Also you may try booting into safe mode and choose "last know good configuration" to get you back before you ran SDFix then try t orun Malwarebytes.


0

Response Number 8
Name: BatchFreak
Date: November 1, 2008 at 09:20:08 Pacific
Reply:

I know its doubtful, but i wasnt going to tell him to put a virus infected harddrive in somone elses computer. I also doubted he had a second computer lying around.

I only Batch if possible, 2000 more lines of code, oh well.


0

Response Number 9
Name: Jack Frost46
Date: November 1, 2008 at 10:31:06 Pacific
Reply:

Hi ,You haven't told you computer specs but it usually f8 , last known good ,

http://support.microsoft.com/defaul...

" jabuck " In another post of his wrote a very neat reg script to start to cure your problem whether this applicable in your case I don't know .
How ever " a cmos virus " I also don't think so , at the very last resort a reinstall of windows but try all other options first .


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Am infected with nasty virus

Infected with a Virus win32.Kilabot www.computing.net/answers/security/infected-with-a-virus-win32kilabot/22595.html

Infected with the b.exe virus!!!! www.computing.net/answers/security/infected-with-the-bexe-virus/26832.html

IE opens when I am browsing with FF www.computing.net/answers/security/ie-opens-when-i-am-browsing-with-ff/22214.html